SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   Application (Multimedia)  >   Adobe Flash Vendors:   Macromedia
(Allaire Issues Fix) Macromedia Flash Player ActionScript Domain Security Flaw Lets Remote Users Access Local Files By Modifying URLs
SecurityTracker Alert ID:  1004993
SecurityTracker URL:  http://securitytracker.com/id/1004993
CVE Reference:   GENERIC-MAP-NOMATCH   (Links to External Site)
Date:  Aug 8 2002
Impact:   Disclosure of system information, Disclosure of user information
Fix Available:  Yes  Vendor Confirmed:  Yes  
Version(s): Prior to 6,0,47,0
Description:   A vulnerability was reported in the Macromedia Flash Player. A remote user can create Flash content that can read local files on the target user's computer.

It is reported that a remote user can create malicious Flash content to read files on the target user's computer and send them to a remote location.

The vulnerability apparently resides in the ActionScript feature used to load XML files. Ordinarily, the Flash Player prevents Flash content (movies) from loading data located outside of the original content's domain. However, it is apparently possible to bypass this restriction by loading data from URLs that are modified during HTTP negotiation. Malicious Flash content served from a remote domain could access local files and send them back to the remote domain.

The following three methods can be used to exploit the flaw, according to the report:

1) The content can force an HTTP redirect to a local file. A demonstration exploit example is available at:

http://kuperus.xs4all.nl/flash.htm

2) The remote user can place a <base href="file:///C:/"> tag in the Flash document then use a relative URL. A demonstration exploit example is available at:

http://www.xs4all.nl/~jkuperus/flash.htm

3) For systems using Internet Explorer, the remote user can embed a malicious Flash object in a web archive ('.mht' file) and make it seem as though its been saved from a location on the users hard drive, then use a relative URL. A demonstration exploit example is available at:

http://www.xs4all.nl/~jkuperus/flash.mht

Impact:   A remote user can create malicious Flash content on a remote server to read files on the target user's computer and send them back to the remote server.
Solution:   Macromedia has released a fixed version (6,0,47,0), available on the Macromedia Player Download Center at:

http;//www.macromedia.com/go/getflashplayer/

Also, the vendor recommends that Macromedia Flash content authors read the following technote:

http://www.macromedia.com/support/flash/ts/documents/load_xdomain.htm

Vendor URL:  www.macromedia.com/v1/handlers/index.cfm?ID=23294 (Links to External Site)
Cause:   Access control error, State error
Underlying OS:   Linux (Any), MacOS, UNIX (OS X), UNIX (SGI/IRIX), UNIX (Solaris - SunOS), Windows (Any)

Message History:   This archive entry is a follow-up to the message listed below.
Aug 8 2002 Macromedia Flash Player ActionScript Domain Security Flaw Lets Remote Users Access Local Files By Modifying URLs



 Source Message Contents

Date:  Thu, 8 Aug 2002 10:29:10 -0700 (PDT)
Subject:  Two Flash Player Security Bulletins: MPSB02-09 and MPSB02-10



~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
IMPORTANT: 
 
Two security issues that may affect Macromedia Flash 
Player have come to our attention recently.

To learn about these new issues and what actions you can
take to address them, Please visit the Security Zone at 
the Macromedia Web site:

http://www.macromedia.com/security
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 

MPSB02-10 - Macromedia Flash URL Modification Issue

http://www.macromedia.com/v1/handlers/index.cfm?ID=23294 

Originally posted: August 8, 2002 
Last updated: August 8, 2002

 
Summary

Macromedia has received a report of vulnerability in the 
Flash Player that could allow maliciously authored Flash 
content, working in conjunction with other content on a 
Web server, to read the contents of files from the local 
file systems of Flash Player users, and send those contents 
back to Web servers without users' consent or knowledge. 
This vulnerability is limited to files whose locations and 
names are known or guessed ahead of time by attackers. An 
attacker would have to entice the user to a site under his 
control to exploit this vulnerability. This vulnerability 
can never be used to modify or delete local files. All 
Macromedia Flash Players are affected. Macromedia has released 
new versions of all Flash Players fixing this issue; see below. 

~~~~~~~~~~~~~ 

Issues

ActionScript in Flash movies can make requests to load data 
directly from files. A common usage of this ability is loading
 XML files from Web servers. As a security measure, the Flash 
Player prevents Flash movies from loading data that originates
 outside the web domain from which the movie was served. This
 restriction naturally extends to files from local file systems.
 The present vulnerability could allow malicious content to 
bypass this same-domain restriction by loading data from URLs 
that are modified during HTTP negotiation, for example by HTTP 
redirects. Data loaded in this way could be sent back to the 
server from which the malicious Flash content was served. 

This vulnerability also existed in the Netscape and Internet 
Explorer browsers, fixed in February and May of 2002 respectively. 
Internet Explorer for the Mac has not been addressed; Macromedia 
is working with Microsoft to ensure that this issue is addressed
 in the near future.

~~~~~~~~~~~~~ 

Solution 

Customers should download the newer Macromedia Flash Player
immediately.

Macromedia Flash content authors should read the following 
technote: 

http://www.macromedia.com/support/flash/ts/documents/load_xdomain.htm. 

~~~~~~~~~~~~~

What Macromedia Is Doing

Macromedia has isolated the issue and released an updated player 
(6,0,47,0) which is available for download on the Macromedia 
Player Download Center 
(http;//www.macromedia.com/go/getflashplayer/). 

Macromedia’s solution to this problem is generalized: the updated 
Flash Players detect all situations in which URLs are modified 
from their original form. This means that if additional methods 
of causing URL modification are discovered, they will not enable 
attackers to bypass the security rules of the Flash Player. 

Macromedia is committed to the security of the Macromedia Flash
 Player, and invests considerable ongoing effort to ensure that
 the security and privacy of all Macromedia Flash Player users 
and all websites serving Macromedia Flash content are protected. 

Macromedia worked together with an external developer to verify
 and fix this issue. Both are committed to security for their 
customers.

Macromedia Shockwave Player includes a “Flash Asset Xtra” that 
enables the playback of Macromedia Flash files within Shockwave 
content. This Flash Asset Xtra is also affected by the issue 
noted above. It will be updated based upon the revised player 
(6,0,47,0) and included in an updated release of Shockwave Player. 
The exact date of this release will be forthcoming shortly.

~~~~~~~~~~~~~

Revisions
August 8, 2002 - Bulletin first released.
 

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 
 

MPSB02-09 - Macromedia Flash Malformed Header Vulnerability 
Issue

http://www.macromedia.com/v1/handlers/index.cfm?ID=23293

 
Originally posted: August 8, 2002 
Last updated: August 8, 2002

 
Summary

Macromedia has recently become aware of a vulnerability where a 
hand edited malformed Macromedia Flash movie (SWF) header can be 
exploited to cause a buffer over-write issue which could 
potentially lead to execution of arbitrary code. 

~~~~~~~~~~~~~

Issues

This can only occur with Macromedia Flash movies (SWF) that 
have been hand edited with a binary editor; Macromedia Flash 
the authoring tool will not output movies with this vulnerability. 

~~~~~~~~~~~~~
 
Solution

Customers should follow the recommendations found in this bulletin
 and download the newer Flash Player when it is available.

~~~~~~~~~~~~~
 
What Macromedia Is Doing

Macromedia has isolated the issue and released an updated player 
(6,0,40,0) which is available for download on the Macromedia Player 
Download Center (at (http;//www.macromedia.com/go/getflashplayer/). 

Macromedia is committed to the security of the Macromedia Flash 
Player, and invests considerable ongoing effort to ensure that 
the security and privacy of all Macromedia Flash Player users 
and all websites serving Macromedia Flash content are protected. 

Macromedia worked together with eEye Digital Security to verify 
and fix this issue. Both companies are committed to security for 
their customers.

~~~~~~~~~~~~~

What Customers Should Do 

Customers should follow the recommendations found in this bulletin
and download the newer Flash Player.

~~~~~~~~~~~~~

Revisions

August 8, 2002 - Bulletin first released.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Reporting Security Issues 

Macromedia is committed to addressing security issues and 
providing customers with the information on how they can 
protect themselves. If you identify what you believe may 
be a security issue with a Macromedia product, please send 
an email to secure@macromedia.com. We will work to appropriately 
address and communicate the issue.  

~~~~~~~

Receiving Security Bulletins 

When Macromedia becomes aware of a security issue that we 
believe significantly affects our products or customers, 
we will notify customers when appropriate. Typically this 
notification will be in the form of a security bulletin 
explaining the issue and the response. Macromedia customers
 who would like to receive notification of new security bulletins 
when they are released can sign up for our security notification 
service. 

For additional information on security issues at Macromedia, 
please visit the Security Zone at:
http://www.macromedia.com/security

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

THE INFORMATION PROVIDED BY MACROMEDIA IN THIS BULLETIN IS 
PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. MACROMEDIA 
AND ITS SUPPLIERS DISCLAIM ALL WARRANTIES, WHETHER EXPRESS 
OR IMPLIED OR OTHERWISE, INCLUDING THE WARRANTIES OF 
MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. 
ALSO, THERE IS NO WARRANTY OF NON-INFRINGEMENT, TITLE OR 
QUIET ENJOYMENT. (USA ONLY) SOME STATES DO NOT ALLOW THE 
EXCLUSION OF IMPLIED WARRANTIES, 

SO THE ABOVE EXCLUSION MAY NOT APPLY TO YOU. IN NO EVENT 
SHALL MACROMEDIA, INC. OR ITS SUPPLIERS BE LIABLE FOR ANY 
DAMAGES WHATSOEVER INCLUDING, WITHOUT LIMITATION, DIRECT, 
INDIRECT, INCIDENTAL, CONSEQUENTIAL, SPECIAL, PUNITIVE, 
COVER,LOSS OF PROFITS, BUSINESS INTERRUPTION OR THE LIKE, 
OR LOSS OF BUSINESS DAMAGES, BASED ON ANY THEORY OF LIABILITY 
INCLUDING BREACH OF CONTRACT, BREACH OF WARRANTY, TORT
(INCLUDING NEGLIGENCE), PRODUCT LIABILITY OR OTHERWISE, 
EVEN IF MACROMEDIA, INC. OR ITS SUPPLIERS 
OR THEIR 
REPRESENTATIVES HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH 
DAMAGES. (USA ONLY) SOME STATES DO NOT ALLOW THE EXCLUSION 
OR LIMITATION OF LIABILITY FOR CONSEQUENTIAL OR INCIDENTAL 
DAMAGES, SO THE ABOVE EXCLUSION OR LIMITATION MAY NOT 
APPLY TO YOU AND YOU MAY ALSO HAVE OTHER LEGAL RIGHTS 
THAT VARY FROM STATE TO STATE. 

Macromedia reserves the right, from time to time, to 
update the information in this document with current 
information.


 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2013, SecurityGlobal.net LLC